<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mcp on CuraSec</title><link>https://curasec.metacog.co.kr/tags/mcp/</link><description>Recent content in Mcp on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 18 Aug 2026 11:37:25 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/mcp/index.xml" rel="self" type="application/rss+xml"/><item><title>MCP Servers Can Silently Expose Enterprise Secrets via Misconfig</title><link>https://curasec.metacog.co.kr/insights/2026-08-18-how-mcp-servers-can-expose-enterprise-secrets/</link><pubDate>Tue, 18 Aug 2026 11:37:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-18-how-mcp-servers-can-expose-enterprise-secrets/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No enrichment signals (no KEV, PoC, or active exploitation), but the attack surface is real: plaintext secrets in MCP config files and over-permissioned access are design-level risks engineers should factor in when deploying AI agent infrastructure. Audit any existing MCP deployments for credential storage and permission scope before expanding use.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, TTPs, or detection artifacts are surfaced here, but the &amp;lsquo;server running before security teams know&amp;rsquo; framing highlights a shadow-AI discovery gap worth tracking. No immediate detection work is possible from this summary alone.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If the organization is adopting AI agents or MCP-based tooling, this is a quarter-horizon governance signal: establish an MCP server inventory policy and access-permission standard before the deployment footprint grows and secret exposure becomes a reportable incident.&lt;/li>
&lt;/ul></description></item><item><title>Malicious MCP Servers Can Exfiltrate Secrets via Instruction Splitting</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-malicious-mcp-servers-can-split-instructions-to-make-ai-codi/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-malicious-mcp-servers-can-split-instructions-to-make-ai-codi/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> AI coding assistants with MCP integrations are actively used in engineering workflows and this technique can bypass safety refusals to steal SSH keys, env secrets, and source code. Audit all connected MCP servers, restrict to explicitly trusted/internal ones, and review what credential stores and source directories your AI assistant can reach.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Instruction-splitting to evade AI safety filters is a novel exfiltration technique worth understanding, but no IOCs, ATT&amp;amp;CK mappings, or detection surface are provided here — file this as an emerging technique to monitor as tooling matures.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Widespread enterprise adoption of AI coding assistants creates a new third-party risk vector: a malicious or compromised MCP server can silently exfiltrate source code and credentials. Establish an approved-MCP-server policy before your engineering teams expand AI tool integrations this quarter.&lt;/li>
&lt;/ul></description></item><item><title>Curated list of MCP servers/agents for DevOps and cloud ops</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-devopsaiguru123-awesome-agentic-devops-52/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-devopsaiguru123-awesome-agentic-devops-52/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Useful reference for evaluating agentic tooling in CI/CD and cloud workflows, particularly the production-access and audit-evidence ratings, but no immediate patching or configuration action required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>